CVE-2020-15152
Summary
| CVE | CVE-2020-15152 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-17 22:15:00 UTC |
| Updated | 2021-05-05 14:02:00 UTC |
| Description | ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version2 2.19.6, 3.1.2, and 4.3.4. More information can be found on the linked advisory. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| fix: disallow PORT connections to alternate hosts · autovance/ftp-srv@e449e75 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| ftp-srv - npm |
MISC |
www.npmjs.com |
Product, Third Party Advisory |
| Server-Side Request Forgery · Advisory · autovance/ftp-srv · GitHub |
CONFIRM |
github.com |
Mitigation, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983063 Nodejs (npm) Security Update for ftp-srv (GHSA-jw37-5gqr-cf9j)